在 gfs2-utils 中发现了一个栈溢出漏洞。 中的元数据遍历(metadata walk)代码使用 时,直接采用了来自磁盘元数据的、未经校验的 inode 高度值,缺乏边界检查。在处理特制的 GFS2 文件系统镜像时,这会导致栈耗尽,从而引发拒绝服务(DoS)问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85150 | 7.5 HIGH | Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_p |
| CVE-2026-71221 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta |
| CVE-2026-71220 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit |
| CVE-2026-84185 | 5.9 MEDIUM | Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification |
| CVE-2026-71222 | 5.3 MEDIUM | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attr |
| CVE-2026-71219 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal |
No comments yet